code-buddy (phuetz/code-buddy) is an MCP server listed on the M8ven Trust Index. It scores 37 out of 100, grade F. It declares 9 tools. No publisher has claimed this listing.

F
Warning
37/100

code-buddy

Local-first AI coding agent for the terminal. 64 LLM providers, 30 of them free or local $0, with auto-failover. 220+ tools, a peer-to-peer fleet, and a desktop app. No API bill required.

Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

phuetz

Source: github_repo_search

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Secret credentials may flow to a network call
6 flows detected: GOOGLE_API_KEY, ELEVENLABS_API_KEY, PEXELS_API_KEY. We can’t prove the destination matches the brand the credential belongs to.
🚨
Reads files from sensitive locations
Touches: ~/.codebuddy/media.env, ~/.codebuddy/media.env, ~/.codebuddy/media.env
🔐
You'll be asked for 16 credentials: ANTHROPIC_API_KEY, CODEBUDDY_SENSORY_TOKEN, GEMINI_API_KEY, GITHUB_TOKEN, GOOGLE_API_KEY, GROK_API_KEY, JWT_SECRET, OPENAI_API_KEY, XAI_API_KEY, BUDDY_SENSE_TOKEN, OPENROUTER_API_KEY, CODEBUDDY_FLEET_TOKEN, PEXELS_API_KEY, GMI_API_KEY, HEYGEN_API_KEY, NVIDIA_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes25 tools · 16 behind config

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

codebuddy_ask

Ask CodeBuddy AI a question and get a response

codebuddy_complete_code

Get AI code completion suggestions

fcs_execute

Execute FCS (FileCommander Script) code

read_file

Read the contents of a file

write_file

Write content to a file

list_directory

List files and directories in a path

search_content

Search for text in files

git_status

Get git repository status

execute_shell

Execute a shell command

agent_chatbehind config

Send a message to the Code Buddy AI agent and get a response with tool call results. Use for conversational interactions.

agent_taskbehind config

Execute an autonomous task using Code Buddy agent. For complex tasks, uses DAG-based planning; for simple tasks, processes directly. Returns all tool calls and results.

agent_planbehind config

Create an execution plan for a task without executing it. Returns the DAG-based task plan with dependencies.

ckg_recallbehind config
ckg_ingestbehind config
desktop_screenshotbehind config

Capture a screenshot of the desktop (fullscreen by default, or a region). Returns the saved PNG path and dimensions. Read-only.

desktop_snapshotbehind config

Enumerate on-screen UI elements (accessibility tree) with numeric refs, roles, labels, and click coordinates. Read-only. Use the returned coordinates with desktop_click.

desktop_clickbehind config

Click the mouse at screen coordinates. Requires CODEBUDDY_MCP_DESKTOP_CONTROL=1. Actuates the real desktop.

desktop_move_mousebehind config

Move the mouse cursor to screen coordinates. Requires CODEBUDDY_MCP_DESKTOP_CONTROL=1.

desktop_typebehind config

Type text at the current focus. Requires CODEBUDDY_MCP_DESKTOP_CONTROL=1. Actuates the real keyboard.

desktop_keybehind config

Press a key (optionally with modifiers), e.g. "enter", "escape", "tab", "f5". Requires CODEBUDDY_MCP_DESKTOP_CONTROL=1.

memory_searchbehind config

Search Code Buddy's semantic memory for relevant stored knowledge, patterns, and context.

memory_savebehind config

Save a piece of knowledge to Code Buddy's persistent memory for future reference.

session_listbehind config

List recent Code Buddy chat sessions with their IDs, names, and timestamps.

session_resumebehind config

Resume a previous Code Buddy session by ID, restoring its chat history and context.

web_searchbehind config

Search the web using Code Buddy's configured search providers (Brave, Perplexity, DuckDuckGo, etc.).

// known CVEs in dependencies1 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

lowvitest@4.1.9GHSA-82fw-gwwq-j7x9

Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configA2A_BRIDGE_DEFAULT_AGENT
configA2A_BRIDGE_DEFAULT_MODEL
configA2A_BRIDGE_DEFAULT_SKILL
🔐 secretANTHROPIC_API_KEY
configANTHROPIC_MODEL
configAUTH_ENABLED
configCHATBOX_PORT
configCHATGPT_MODEL
configCODEBUDDY_A2A_PUBLIC_URL
configCODEBUDDY_AUDIT_DIR
configCODEBUDDY_BUNDLED_SKILLS_DIR
configCODEBUDDY_CLI
configCODEBUDDY_CLI_VERSION
configCODEBUDDY_COGNITION_METRICS_EVERY
configCODEBUDDY_COGNITIVE_SPECIALISTS
configCODEBUDDY_COGNITIVE_SPECIALIST_MAX_PER_HOUR
configCODEBUDDY_CONVERSATION_EVAL_COOLDOWN_MS
configCODEBUDDY_CONVERSATION_EVAL_EVERY
configCODEBUDDY_CONVERSATION_EVAL_MIN_STREAK
configCODEBUDDY_DISABLE_MCP
configCODEBUDDY_DREAM_EVERY
configCODEBUDDY_EPISODE_EVERY
configCODEBUDDY_FLEET_HOSTNAME
configCODEBUDDY_FLEET_MACHINE_LABEL
configCODEBUDDY_FLEET_REPO_PATH
configCODEBUDDY_FLEET_TICK_INTERVAL_MS
configCODEBUDDY_HEADLESS
configCODEBUDDY_HEARTBEAT_EVERY
configCODEBUDDY_INNER_LIFE_EVERY
configCODEBUDDY_JOKES_TOPUP_EVERY
configCODEBUDDY_LISA_SELFIE_REFILL_EVERY
configCODEBUDDY_LLM_ORDER
configCODEBUDDY_LOCALE
configCODEBUDDY_MCP_DESKTOP_CONTROL
configCODEBUDDY_MODEL_FALLBACK_WARNED
configCODEBUDDY_PIPER_BIN
configCODEBUDDY_PREFETCH_INTERVAL_MS
configCODEBUDDY_PROVIDERForce the local Ollama path (no API key).
configCODEBUDDY_QUIET
configCODEBUDDY_SCHEDULE_TICKS_EVERY
configCODEBUDDY_SELF_IMPROVE_PROPOSER
configCODEBUDDY_SENSORY_CAMERA
configCODEBUDDY_SENSORY_SPEAK_CWD
configCODEBUDDY_SENSORY_SPEAK_FACT_MODEL
configCODEBUDDY_SENSORY_SPEECH
🔐 secretCODEBUDDY_SENSORY_TOKEN
configCODEBUDDY_SERVER_CHANNEL_INTAKE
configCODEBUDDY_SESSION_END_FLUSH_TIMEOUT_MS
configCODEBUDDY_SYSTEM_VITALS_EVERY
configCODEBUDDY_VOICE_IMPROVE_EVERY
configCODEBUDDY_VOICE_MODEL_REFRESH_MS
configCORS_ORIGINS
🔐 secretGEMINI_API_KEY
configGEMINI_MODEL
configGITHUB_ACTIONS
🔐 secretGITHUB_TOKEN
🔐 secretGOOGLE_API_KEY
🔐 secretGROK_API_KEY
configGROK_BASE_URL
configGROK_FORCE_TOOLS
configGROK_MODEL
configGROK_SKIP_PERMISSIONS
configGROK_VIM_MODE
configHOST
configJWT_EXPIRATION
🔐 secretJWT_SECRETRequired by the HTTP server in production.
configLMSTUDIO_HOST
configLOGGING
configLOG_LEVEL
configMAX_COST
configMAX_REQUEST_SIZE
configMCP_DEBUG
configMETRICS_CONSOLE
configMETRICS_FILE
configMETRICS_INTERVAL
configMETRICS_PATH
configOLLAMA_HOST
configOLLAMA_MODEL
🔐 secretOPENAI_API_KEY
configOPENAI_BASE_URL
configOPENAI_MODEL
configPERF_TIMING
configRATE_LIMIT_MAX
configRATE_LIMIT_WINDOW
configSECURITY_HEADERS
configWS_ENABLED
🔐 secretXAI_API_KEY
configYOLO_MODEFull autonomy with guardrails. Setting YOLO_MODE=true alone only warns; it does not arm it.
configBUDDY_SENSE_BRIDGE_URL
🔐 secretBUDDY_SENSE_TOKEN
configBUDDY_EAR_DEVICE
configBUDDY_EAR_RMS_ON
configBUDDY_EAR_RMS_OFF
configBUDDY_EAR_MIN_MS
configBUDDY_EAR_MAX_MS
configBUDDY_EAR_HANG_MS
configBUDDY_EAR_WAV_DIR
configBUDDY_SENSE_CAMERA_INDEX
configBUDDY_VISION_CAMERA_NAME
configBUDDY_SENSE_FRAME_DIR
configBUDDY_VISION_EVENTS_LOG_MAX_BYTES
configBUDDY_VISION_FPS
configBUDDY_VISION_MOTION
configBUDDY_VISION_MIN_LUMA
configBUDDY_VISION_NOISE_WINDOW
configBUDDY_VISION_PERSON_BACKEND
configBUDDY_VISION_YOLO_MODEL
configBUDDY_VISION_YOLO_CONF
configBUDDY_VISION_YOLO_IOU
configBUDDY_VISION_YOLO_DEVICE
configBUDDY_VISION_YOLO_CLASSES
configBUDDY_VISION_MAX_PERSONS
configBUDDY_VISION_TRACK_IOU
configBUDDY_VISION_MOTION_FRAME_SLOTS
configBUDDY_VISION_SEMANTIC_FRAME_SLOTS
configBUDDY_VISION_PERSON_LOST_SECS
configBUDDY_VISION_HEARTBEAT_SECS
configBUDDY_VISION_CAMERA_FAILURE_GRACE
configBUDDY_VISION_MOTION_EVENT_SECS
configBUDDY_VISION_BLINK
configBUDDY_VISION_DROWSY_SECS
configBUDDY_VISION_DETECTORS
configBUDDY_VISION_OBSERVATION_SECS
🔐 secretOPENROUTER_API_KEY
🔐 secretCODEBUDDY_FLEET_TOKEN
configRANK
configLOCAL_RANK
configCUDA_VISIBLE_DEVICES
configCODEBUDDY_GPU_MAX_TEMP_C
configCODEBUDDY_GPU_JOB_RESULT
configCODEBUDDY_GPU_ALLOWED_ROOTS_JSON
configCODEBUDDY_PANOWORLD_COMMIT
configCODEBUDDY_PANOWORLD_CANCEL_GRACE_SECONDS
configCODEBUDDY_PANOWORLD_ROOT
configHF_HOME
configINFLUENCER_WORKDIR
configCOMFYUI_URL
configBROLL_OUT
configBROLL_SIZE
configBROLL_QUALITY
configBROLL_LENGTH
configINFLUENCER_RSS_FEEDS
configINFLUENCER_RANKING_LIMIT
configFLOW_PROJECT_ID
configFLUX_CKPT
configFLUX_CLIP_L
configFLUX_T5
configFLUX_VAE
🔐 secretPEXELS_API_KEY
🔐 secretGMI_API_KEY
configGROK_IMAGINE_LOG
configGROK_IMAGINE_REFRESH
configGROK_IMAGINE_POLL_ATTEMPTS
configGROK_IMAGINE_POLL_INTERVAL
configGROK_IMAGINE_BACKUP
configVIDEO_FONT
configVIDEO_MUSIC
configVIDEO_NO_MUSIC
🔐 secretHEYGEN_API_KEY
configVEILLE_YOUTUBE_MODEL
configVEILLE_YOUTUBE_ENGINE
configVEILLE_YOUTUBE_COOKIES
configVEILLE_YOUTUBE_COOKIES_FROM_BROWSER
configOMNIROUTE_ROOT
configNVIDIA_BASE_URL
🔐 secretNVIDIA_API_KEY
configCODEBUDDY_QA_NODE
configRECETTE_QA_BASE
configCODEBUDDY_SESSIONS_DIR
configRECETTE_RESUME_ID
configCODEBUDDY_ELEVENLABS_MONTHLY_CAP
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployPORT
deploySENTRY_DSN
// quality suggestions

Dependencies

51 runtime dependencies (27 dev), 1 flagged: playwright-core

Tool inputs are validated

16/25 tool handlers declare input schemas (64%)

Declare an inputSchema with zod/joi/yup on every tool definition.

No access to sensitive paths

Reads sensitive paths: ~/.codebuddy/media.env, ~/.codebuddy/media.env, ~/.codebuddy/media.env

Remove reads of sensitive system paths. If you genuinely need them, document why in the README.

Shell command execution

4 calls in production code run through a shell (src/action/index.ts:84, src/doctor/index.ts:86, src/doctor/index.ts:518)

Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.

Dependency freshness

3/51 production deps abandoned (no release in 2+ years): diff-match-patch@2022-06-15 (4.3y), cli-highlight@2023-04-12 (3.4y), @iarna/toml@2023-07-15 (3.2y)

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 3 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/phuetz/code-buddy?variant=verified)](https://m8ven.ai/mcp/phuetz/code-buddy)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: ce78efe854631541f29ae2dd76845e308bc1d365
code hash: a8638ff8ccafa52cfafd949a4f583575bca77992e9a35dba4f4d46ce64b25b67
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client